Skip to main content
compliance · aws

Provisioned-capacity DynamoDB tables with no auto scaling configured

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags a DynamoDB table in `PROVISIONED` billing mode that has no Application Auto Scaling target, checked with `application-autoscaling:DescribeScalableTargets`. On-demand tables are excluded because they have no capacity units to scale. A provisioned table with fixed capacity either throttles at peaks or pays for idle read and write units the rest of the time.

Signal and threshold

How ZopNight evaluates Provisioned-capacity DynamoDB tables with no auto scaling configured.
Field Value
Rule IDsRC-1515
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdprovisioned mode with no scalable target
SourceZopNight
Permissions useddynamodb:ListTables · dynamodb:DescribeTable · application-autoscaling:DescribeScalableTargets

Fixed capacity on a provisioned table

A DynamoDB table in provisioned mode is billed for the read and write capacity units you set, whether you use them or not. The DynamoDB auto scaling guide describes Application Auto Scaling adjusting that provisioned throughput so a table absorbs sudden increases without throttling, then decreases it “so that you don’t pay for unused provisioned capacity”. Target utilization can be set between 20 and 90 percent. Without it, capacity is whatever someone typed in last, which is usually sized for a peak that happens a few hours a week.

Listing tables and their scaling targets

Tables with auto scaling appear as scalable targets such as table/orders with the dynamodb:table:ReadCapacityUnits dimension:

Terminal window
aws application-autoscaling describe-scalable-targets --service-namespace dynamodb \
--query 'ScalableTargets[].[ResourceId,ScalableDimension,MinCapacity,MaxCapacity]' \
--output table

Compare with each table’s billing mode:

Terminal window
aws dynamodb describe-table --table-name orders \
--query 'Table.[TableName,BillingModeSummary.BillingMode,ProvisionedThroughput]'

A provisioned table missing from the first list has no auto scaling.

Three facts must line up

The finding fires only when ZopNight knows the table’s billing mode, the mode is provisioned, and the auto scaling check explicitly came back with no scalable target. All three must be present.

On-demand tables and missing data

Application Auto Scaling only works on provisioned capacity. An on-demand (PAY_PER_REQUEST) table has nothing to register, so it always returns zero targets; ZopNight skips those tables instead of suggesting something impossible. It also stays silent when the billing mode or the auto scaling answer was not collected.

Where the money is, even at $0

The finding is reported at $0, but the effect on spend is direct: capacity that tracks demand costs less than capacity pinned at peak. For tables with steady traffic on on-demand pricing, see DynamoDB On-Demand Billing with Steady Traffic for the opposite case.

Enabling auto scaling

  1. In the DynamoDB console, open the table’s capacity settings and turn on auto scaling for read and write capacity.
  2. Start with a target utilization of 70% and a minimum that covers your quietest hour.
  3. For spiky or unpredictable tables, consider switching to on-demand: aws dynamodb update-table --table-name orders --billing-mode PAY_PER_REQUEST.
  4. Watch ConsumedReadCapacityUnits and ConsumedWriteCapacityUnits against provisioned values for a week.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·